Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Who should own risk appetite updates and reviews?
Governance, Ownership & Risk

Who should own risk appetite updates and reviews?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

The board and senior leadership should set direction, but operational owners need to maintain the statement and keep it aligned to changing business conditions. Review responsibilities should be explicit so appetite does not become stale when objectives, regulations, or risk exposure shift. Clear ownership is part of making governance enforceable.

How should ownership be split between the board and management?

risk appetite is a governance instrument, so the board should own the approved direction and the tolerance the organisation is willing to accept. Management should own the operating statement, proposed changes, and the cadence that keeps it usable. In practice, ownership works best when strategy is set at the top and day-to-day maintenance sits with the people closest to changing risk exposure.

That split matters because appetite is only useful when it can be translated into decisions about growth, controls, exceptions, and escalation. If the board tries to manage the wording itself, the statement tends to lag operations. If management owns it without clear board oversight, appetite can drift away from the organisation’s actual risk posture.

What should operational owners actually maintain?

Operational owners should keep the statement aligned to business model changes, control maturity, regulatory shifts, and emerging exposures. That includes proposing revisions, validating thresholds against current performance, and making sure the language still maps to how the organisation makes trade-offs in practice. Ownership should be explicit enough that updates do not depend on informal follow-up or annual memory.

Good ownership also means separating content maintenance from approval authority. Management can prepare the analysis and draft revisions, but the board or delegated committee should approve material changes. That separation preserves accountability while still letting the organisation react quickly when appetite needs to move.

For teams working on complex digital or AI-enabled environments, the same principle applies to board-level risk briefing and appetite questions: the people running the programme need to maintain the working statement, but the governing body must own the tolerance boundary.

How often should appetite be reviewed, and what should trigger change?

Review cadence should be regular, but the trigger should be event-driven as well as calendar-driven. A review should happen when objectives change, when regulations shift, when risk exposure moves materially, or when the organisation’s control environment changes enough that the old wording no longer matches reality. The right question is not whether the annual review happened, but whether the statement still reflects current business intent.

That means the review process should include a clear change threshold. Minor wording adjustments may stay with management, while material shifts in tolerance, scope, or decision authority should go back to the board. Without that distinction, appetite can become stale at exactly the point where the business most needs it to guide decisions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyRisk appetite updates define how the organisation sets and reviews its risk tolerance.
GV.RM-02 — Risk Management Roles and ResponsibilitiesOwnership and review duties must be explicit for appetite to remain enforceable.
Recommendation — Set and review risk appetite through a documented risk management strategy. Assign clear accountability for maintaining and approving risk appetite changes.
ISO/IEC 27001:2022A.5.4 — Management responsibilitiesGovernance ownership for security-related decisions must be assigned and maintained.
A.5.1 — Policies for information securityRisk appetite functions like a top-level policy statement that needs ongoing review.
Recommendation — Assign management responsibility for maintaining and reviewing governance statements. Review policy statements regularly so they stay aligned with current risk.

Practitioner Guidance

What to prioritise: Define a single accountable owner for upkeep, then define a separate approving authority for material changes. That prevents a common failure mode where everyone references risk appetite, but no one is clearly responsible for refreshing it.

What to verify: Confirm that every appetite statement has a review cadence, a trigger list, and an escalation path for material changes. If those elements are absent, the statement is more of a policy artifact than an operational governance tool.

Decision rule: If the change affects the organisation’s willingness to accept risk, board reapproval is needed; if it only updates wording, metrics, or supporting detail, management can maintain it under delegated authority.

Practitioner takeaway: The most effective model is board-owned direction with management-owned maintenance, because appetite stays credible only when the people closest to changing conditions are responsible for keeping it current.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org